Ranzy Locker is a ransomware operation active since late 2020 that is widely described as a rebranded and improved successor to ThunderX, with infrastructure overlap also noted with Ako. The group operated a ransomware-as-a-service model and used double extortion, stealing sensitive data before encrypting victim systems and threatening public release to coerce payment. Victims were reported across manufacturing, government, transportation, and information technology, and U.S. businesses were prominently affected, with more than 30 compromises reported by mid-2021. Ranzy Locker obtained access through multiple vectors, including exploitation of Microsoft Exchange Server vulnerabilities, phishing, Remote Desktop Protocol access using valid accounts, and brute-force activity. Post-compromise behavior included discovery of mounted drives, network shares, remote systems, running processes, and attached media, as well as searching for high-value data for exfiltration such as customer information, personally identifiable information, and financial records. The malware and associated operator activity also included anti-debugging checks, configuration obfuscation, deletion of backups and shadow copies, and disabling of Windows recovery features to hinder restoration. For impact, Ranzy Locker encrypted files using Salsa20, with per-file key protection via RSA-2048, and deployed ransom notes directing victims to attacker-controlled payment communications. The operation is associated with leak-site activity and affiliate-based deployment consistent with big-game ransomware practices.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in a list of ransomware groups known for affiliate programs and leak blogs.
Ransomware operators running a RaaS model and double-extortion campaign, compromising organizations and encrypting/exfiltrating data.
Mentioned only in comparative leak-site statistics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.